The Polish Data Protection Authority, also known as the ODO police.

08 kwietnia 2013

When can we expect an inspection by the Polish Data Protection Authority? What does such an inspection look like in practice? What is its purpose? How can we prepare for it? What could be the consequences if it turns out that we are violating the Personal Data Protection Act? What else does the Polish Data Protection Authority do besides conducting inspections? All of this is discussed below. It turns out that the Chief Data Protection Officer (GIODO) conducts inspections only in truly exceptional situations – most often as a result of a significant incident (e.g., a large data breach), and much less frequently for preventive purposes. In 2011, a total of 199 inspections were carried out, and in 2012, 165. On a national scale, this is very few. Over these years, a total of 20 notifications of suspected crimes related to personal data protection were recorded. To improve these statistics and better ensure data protection, in December 2012, the Polish Data Protection Authority signed an agreement for joint inspections with the National Labor Inspectorate (PIP), which conducts 90,000 inspections annually across the country.

Control in Practice.

The control by the Polish Data Protection Authority is usually announced a few days (7 days) prior to the arrival of the inspectors. Therefore, the entrepreneur has time to prepare calmly for it. The notification of the control most often specifies its scope and information on what needs to be prepared. The control is conducted as part of the control plan, which is a document

GDPR Bulletin
Receive a package of free GDPR guides and micro-trainings
Join the ranks of our newsletter readers, receive a free package, and stay informed.
RECEIVE PACKAGE
defining its purpose and scope as well as the anticipated completion date. It is usually conducted by a three-person inspection team (2 lawyers and one IT specialist). Upon presentation of a named authorization and an official ID, the inspectors have the right to enter all premises where personal data is processed. According to the law, the control can take place from 6:00 AM to 10:00 PM; however, in practice, regular working hours of 8:00 AM to 4:00 PM are generally observed. Virtually everything that in any way relates to personal data may be checked. However, inspections most often focus on five main issues: legal bases for processing personal data, appropriate data security measures, purpose and scope of data processing, fulfillment of information obligations by the data controller, and registration of data sets. The control concludes with the preparation of a protocol, to which we can add our comments, sign it, or refuse to sign.

If the control reveals any deficiencies, the inspector will request the Polish Data Protection Authority to issue an administrative decision ordering their removal. The outcome of the control may also be the initiation of administrative proceedings, as a result of which a fine of up to PLN 200,000 may be imposed on the entrepreneur, and PLN 50,000 on an individual.

Notification of Control by the Polish Data Protection Authority and…

We have received a notification of an inspection. What now? First and foremost, do not panic! Even if we do not have any documentation, a Data Protection Officer, or trained staff, we can still save ourselves, especially if our business is small (employing fewer than 50 employees). It is essential to create documentation for personal data protection. Of course, inspectors will notice that the date of the document is later than the notification of the inspection, but it will always look better than having nothing at all. After receiving the notification of the inspection, there may be ideas to create documentation with a backdated timestamp. However, we strongly advise against such practices. Falsifying company documentation can lead to liability under the provisions of the Penal Code and the Fiscal Penal Code, which can have truly serious consequences.

Remaining activities of the Polish DPA.

In addition to conducting inspections and issuing decisions, the Polish DPA is responsible for the registration of personal data sets that are subject to registration. The register is maintained for the transparency of data processing, allowing any interested party to check which company manages which set of data. Furthermore, an important task of the Polish DPA is to promote knowledge about personal data protection – it conducts educational activities for this purpose – as well as to advocate for necessary changes in the law regarding data protection.

In conclusion…

Polish DPA Inspection - for us, it's routine!

In summary, an inspection is nothing to be afraid of if we meet the requirements of the regulation and the Personal Data Protection Act. However, it can cost us dearly if we do absolutely nothing to ensure the security of the data we process. To know how to do this, it is worth taking a closer look at the educational activities of the Polish DPA, and of course, reading our blog!

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.